I was wondering about the specification of SOC4, and differences between models, do did a little digging and investigation, wonder if you might find interesting.
CPU
SOC4 has 8 cores total, this is the easiest metric to compare to the performance, looking at SSL VPN that is largely CPU bound you see the 4 core 40f lags at 490mbs, 60f 900mbs, 100f 1gbs. So we know 40f is 4 cores and everything else is 8 cores, but we also see some small CPU speed binning between the models.
Memory
40f, 60f 2GB, 80f, 100f 4GB. This has a direct impact to scaling, number of sessions, but little "throughput" difference.
CP processor
CP9XLite has 5 IPsec VPN engines (aka CP cores), taken from the following guide.
https://docs.fortinet.com...40357/cp9-capabilities - For example, the CP9 has sixteen IPsec VPN engines while the CP9XLite has five and the CP9Lite has one.
Looking at the CP dependent traffic you can see a trend. 40f 4.4gbs ipsec, 310mbs SSL inspection = 2 CP cores 60f/80f 6.5gbs ipsec, 630mbs SSL inspection = 3 CP cores 100f 11.5gbs ipsec, 1gbs SSL inspection = 5 CP cores
NP processor
The following spec gives a little detail about the NP6XLite, it appears to be quite the beast. The main difference will be the interface connection to physical ports. It has 2 x 1GB ports we often see directly connected, on 60f and 80f these are directly connected to WAN1 and 2, interestingly these will probably have slightly lower latency. Everything else is connected internally vis a switch fabric and a LAG group over them 10GB USXGMII interfaces to the NP. Other then port differences I am not aware of any performance differences, welcome to comments :)
https://docs.fortinet.com...94/np6xlite-processors
NP6XLite processors The NP6XLite works the same way as the NP6 and supports all the same functionality as the NP6 processor, including CAPWAP, Syn proxy, and DNS session helper offloading. The NP6XLite has slightly lower throughput (36Gbps) than the NP6 (40Gbps). The NP6XLite has a maximum throughput of 36 Gbps using 4x KR/USXGMII/QSGMII and 2x(1x) Reduced gigabit media-independent interface (RGMII) interfaces.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.